PT-2024-9619 · Gstreamer+11 · Gstreamer+11

Antonio Morales

+1

·

Published

2024-10-02

·

Updated

2025-06-30

·

CVE-2024-47613

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GStreamer versions prior to 1.24.10
Description A null pointer dereference vulnerability has been identified in the gst gdk pixbuf dec flush function within gstgdkpixbufdec.c. This function invokes memcpy, using out pix as the destination address. out pix is expected to point to the frame 0 from the frame structure, which is read from the input file. However, in certain situations, it can point to a NULL frame, causing the subsequent call to memcpy to attempt writing to the null address (0x00), leading to a null pointer dereference. This can result in a Denial of Service (DoS) by triggering a segmentation fault (SEGV).
Recommendations Update to version 1.24.10 to fix the vulnerability. As a temporary workaround, consider disabling the gst gdk pixbuf dec flush function until a patch is available. Restrict access to the gstgdkpixbufdec.c module to minimize the risk of exploitation. Avoid using the out pix variable in the affected function until the issue is resolved.

Exploit

Fix

DoS

Memory Corruption

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2024:11122
ALSA-2024:11299
ALSA-2024_11122
ALSA-2024_11299
ALT-PU-2025-2299
ALT-PU-2025-7574
AZL-62336
BDU:2024-11331
CESA-2024_11299
CVE-2024-47613
DLA-4071-1
DSA-5838-1
INFSA-2024_11122
INFSA-2024_11299
MGASA-2025-0040
OESA-2024-2592
OESA-2024-2593
OESA-2024-2594
OESA-2024-2595
OESA-2024-2596
OPENSUSE-SU-2024:14578-1
OPENSUSE-SU-2025_0055-1
OPENSUSE-SU-2025_0064-1
OPENSUSE-SU-2025_0067-1
RHSA-2024:11119
RHSA-2024:11121
RHSA-2024:11122
RHSA-2024:11148
RHSA-2024:11149
RHSA-2024:11298
RHSA-2024:11299
RHSA-2024:11344
RHSA-2024:11346
RHSA-2024:11348
RHSA-2024_11122
RHSA-2024_11299
RLSA-2024:11122
RLSA-2024:11299
SUSE-SU-2025:00063-1
SUSE-SU-2025:0052-1
SUSE-SU-2025:0055-1
SUSE-SU-2025:0063-1
SUSE-SU-2025:0064-1
SUSE-SU-2025:0067-1
SUSE-SU-2025:02055-1
SUSE-SU-2025_02055-1
USN-7176-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Gstreamer
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu